Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-74767: CWE-434 Unrestricted Upload of File with Dangerous Type in pandora-analysis pandora

0
High
VulnerabilityCVE-2026-74767cvecve-2026-74767cwe-434
Published: 08/15/2026 (08/15/2026, 21:56:44 UTC)
Source: CVE Database V5
Vendor/Project: pandora-analysis
Product: pandora

Description

Pandora before version 1.12.6 contains a denial-of-service vulnerability due to unbounded decompression of DAA archive files. An attacker can submit a crafted DAA file with highly compressed data that expands to a large size in memory, causing excessive memory and CPU usage. This can make the extraction worker unresponsive or terminate it, impacting Pandora's availability. The vulnerability is tracked as CVE-2026-74767 with a high severity score of 8.7.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
Low
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L

Affected software

GitHub Actionsmore threats →cve
pandora
pkg:github/pandora
Affected versions
<=1.12.5

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 22:26:04 UTC

Technical Analysis

Pandora's handling of Direct Access Archive (DAA) files includes a denial-of-service vulnerability (CWE-434) where compressed chunks are decompressed without limits on the uncompressed size. This allows an attacker to craft a DAA file that decompresses into a very large amount of data, exhausting memory and CPU resources during extraction of the internal ISO image. The vulnerability affects Pandora versions up to and including 1.12.5. The patch introduces bounded decompression with a maximum extracted file size limit and raises a ZipBomb exception if exceeded, aborting extraction and preventing resource exhaustion.

Potential Impact

Successful exploitation results in denial of service by exhausting memory and CPU resources on the Pandora service, causing extraction workers to become unresponsive or terminate. This impacts the availability of the Pandora service but does not indicate privilege escalation, data disclosure, or integrity compromise.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The described patch approach uses bounded decompression with limits on uncompressed data size and aborts extraction when limits are exceeded. Until an official fix is available, avoid processing untrusted DAA files or implement resource usage monitoring to detect abnormal decompression behavior.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CIRCL
Date Reserved
2026-08-15T21:56:41.828Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a80e422bf8831d539c6ce9f

Added to database: 08/15/2026, 22:11:46 UTC

Last enriched: 08/15/2026, 22:26:04 UTC

Last updated: 08/15/2026, 23:32:56 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses